EXPOSURES › CVE-2021-30116
CVE-2021-30116
CRITICAL ⌖ ON CISA KEV · EXPLOITEDKaseya VSA exposed session IDs, enabling attackers to compromise systems and potentially deploy ransomware.
A vulnerability in Kaseya VSA allowed attackers to obtain session IDs, facilitating further attacks and potentially ransomware deployment. DIB organizations using VSA face significant exposure and compliance risks (CMMC DF, MP) and must immediately patch and review access controls. This incident highlights the importance of vendor risk management and timely patching.
Shame score — The exposure of session IDs enabled unauthorized access and potential ransomware deployment, demonstrating a significant security oversight by Kaseya.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.
"Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system."